Загрузка...

Cybersecurity Week In Review: Zero-Days, VPN Exploits, and Supply Chain Risk

This week in cybersecurity, we break down five of the biggest stories shaping the threat landscape right now.

Microsoft is investigating RoguePlanet, a newly released Microsoft Defender zero-day exploit that reportedly grants SYSTEM privileges on fully patched Windows systems. Meanwhile, CISA has ordered federal agencies to urgently patch a critical Check Point flaw that has already been exploited, with at least one incident linked to the Qilin ransomware-as-a-service operation.

Google also pushed an emergency Chrome update for CVE-2026-11645, marking the fifth Chrome zero-day patched so far this year. And GitHub temporarily disabled 73 Microsoft repositories after concerns they were distributing potentially malicious content tied to the Miasma/Shai-Hulud supply-chain campaign.

The FBI and Justice Department also seized 13 domains allegedly tied to a China-linked intelligence collection effort targeting current and former U.S. government employees, military personnel, and security clearance holders through fake consulting sites and job offers.

Across these stories, the larger theme is clear: attackers are continuing to pressure the edges of trust, from endpoint security tools and VPN access to browsers, code repositories, and recruiting platforms used for intelligence collection.

If you want cybersecurity news explained clearly, conversationally, and without the fluff, this is your weekly recap.

Stories covered in this episode:

Microsoft Defender RoguePlanet zero-day grants SYSTEM privileges
https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/

CISA orders feds to patch Check Point flaw exploited by ransomware gangs
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs/

Google patches fifth Chrome zero-day bug exploited in attacks this year
https://www.bleepingcomputer.com/news/security/google-patches-fifth-chrome-zero-day-bug-exploited-in-attacks-this-year/

GitHub disables Microsoft repos pushing password-stealing malware
https://www.bleepingcomputer.com/news/security/github-disables-microsoft-repos-pushing-password-stealing-malware/

The FBI seizes China-linked fake consulting sites targeting U.S. clearance holders
https://hackread.com/fbi-seizes-china-fake-consulting-sites-us-clearance/
0:00 - Intro
1:03 - RoguePlanet
3:01 - Check Point VPN
5:01 - Google Chrome
6:19 - Microsoft GitHub
7:50 - FBI
10:14 - Closing

Видео Cybersecurity Week In Review: Zero-Days, VPN Exploits, and Supply Chain Risk канала White Hat Wes
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять